1. Web Security Academy
  2. SQL injection
  3. Lab

Lab: SQL injection vulnerability allowing login bypass


This lab contains an SQL injection vulnerability in the login function.

To solve the lab, perform an SQL injection attack that logs in to the application as the administrator user.

Stories from the Daily Swig about SQL injection

Find SQL injection vulnerabilities using Burp Suite

The benefits of working through PortSwigger's Web Security Academy

Get started with the Web Security Academy where you can practise exploiting vulnerabilities on realistic targets .. and its free!

Already got an account? Login here